WO2007127035A3 - Systeme et procede de mise en œuvre de re-authentification rapide - Google Patents

Systeme et procede de mise en œuvre de re-authentification rapide Download PDF

Info

Publication number
WO2007127035A3
WO2007127035A3 PCT/US2007/008632 US2007008632W WO2007127035A3 WO 2007127035 A3 WO2007127035 A3 WO 2007127035A3 US 2007008632 W US2007008632 W US 2007008632W WO 2007127035 A3 WO2007127035 A3 WO 2007127035A3
Authority
WO
WIPO (PCT)
Prior art keywords
client
server
authentication
sgw
reauthentication
Prior art date
Application number
PCT/US2007/008632
Other languages
English (en)
Other versions
WO2007127035A2 (fr
Inventor
Kevin Shatzkamer
Anand K Oswal
Mark Grayson
Jayaraman Iyer
Navan Narang
Original Assignee
Cisco Tech Inc
Kevin Shatzkamer
Anand K Oswal
Mark Grayson
Jayaraman Iyer
Navan Narang
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Cisco Tech Inc, Kevin Shatzkamer, Anand K Oswal, Mark Grayson, Jayaraman Iyer, Navan Narang filed Critical Cisco Tech Inc
Priority to CN2007800152286A priority Critical patent/CN101432717B/zh
Priority to EP07755042.4A priority patent/EP2011270B1/fr
Publication of WO2007127035A2 publication Critical patent/WO2007127035A2/fr
Publication of WO2007127035A3 publication Critical patent/WO2007127035A3/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/164Implementing security features at a particular protocol layer at the network layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/72Subscriber identity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/16Gateway arrangements

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

La présente invention concerne un système de ré-authentification efficace d'un client d'un réseau. Dans un mode de réalisation spécifique, le système comprend un serveur d'authentification et une passerelle de sécurité (SGW) en communication avec le client. La SGW comprend des informations de ré-authentification associées au client. Dans un mode de réalisation plus spécifique, le serveur d'authentification comprend un serveur d'authentification, d'autorisation et de comptabilisation (AAA). La SGW comprend en outre une ou plusieurs routines destinées à l'emploi des informations de ré-authentification pour ré-authentifier le client. Le serveur AAA effectue une authentification initiale du client pour permettre au client d'accéder au réseau, ce qui produit les informations de ré-authentification. Les informations de ré-authentification comprennent une ou plusieurs clés et/ou compteurs, tels qu'une clé d'autorisation, une clé de chiffrement et une clé principale, qui est/sont prédéterminé(s) par le serveur AAA.
PCT/US2007/008632 2006-04-26 2007-04-04 Systeme et procede de mise en œuvre de re-authentification rapide WO2007127035A2 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN2007800152286A CN101432717B (zh) 2006-04-26 2007-04-04 用于实现快速再认证的***和方法
EP07755042.4A EP2011270B1 (fr) 2006-04-26 2007-04-04 Système et procédé de mise en oeuvre de ré-authentification rapide

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US11/411,482 US8356171B2 (en) 2006-04-26 2006-04-26 System and method for implementing fast reauthentication
US11/411,482 2006-04-26

Publications (2)

Publication Number Publication Date
WO2007127035A2 WO2007127035A2 (fr) 2007-11-08
WO2007127035A3 true WO2007127035A3 (fr) 2008-12-11

Family

ID=38649796

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2007/008632 WO2007127035A2 (fr) 2006-04-26 2007-04-04 Systeme et procede de mise en œuvre de re-authentification rapide

Country Status (4)

Country Link
US (1) US8356171B2 (fr)
EP (1) EP2011270B1 (fr)
CN (1) CN101432717B (fr)
WO (1) WO2007127035A2 (fr)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109413646A (zh) * 2017-08-16 2019-03-01 华为技术有限公司 安全接入方法、设备及***

Families Citing this family (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7237117B2 (en) 2001-03-16 2007-06-26 Kenneth P. Weiss Universal secure registry
EP1987463A1 (fr) 2006-02-21 2008-11-05 WEISS, Kenneth P. Procédé et appareil pour paiement d'accès sécurisé et identification
US8234220B2 (en) 2007-02-21 2012-07-31 Weiss Kenneth P Universal secure registry
US11227676B2 (en) 2006-02-21 2022-01-18 Universal Secure Registry, Llc Universal secure registry
US8356171B2 (en) 2006-04-26 2013-01-15 Cisco Technology, Inc. System and method for implementing fast reauthentication
US9053063B2 (en) * 2007-02-21 2015-06-09 At&T Intellectual Property I, Lp Method and apparatus for authenticating a communication device
KR100964350B1 (ko) * 2007-09-14 2010-06-17 성균관대학교산학협력단 IPv6 환경에서의 SEND와 IPSec 협업 기법 및시스템
CN101616407B (zh) * 2008-06-25 2011-04-27 华为技术有限公司 预认证的方法和认证***
US8245039B2 (en) * 2008-07-18 2012-08-14 Bridgewater Systems Corp. Extensible authentication protocol authentication and key agreement (EAP-AKA) optimization
KR101015254B1 (ko) 2009-02-10 2011-02-18 주식회사 케이티 의사 가입자식별번호를 사용한 위치 등록 제어 시스템 및 그 방법
US8555069B2 (en) * 2009-03-06 2013-10-08 Microsoft Corporation Fast-reconnection of negotiable authentication network clients
JP2011023854A (ja) * 2009-07-14 2011-02-03 Sony Corp 情報処理装置、情報処理方法およびプログラム
US8578465B2 (en) 2009-07-21 2013-11-05 Cisco Technology, Inc. Token-based control of permitted sub-sessions for online collaborative computing sessions
CN101754422B (zh) * 2009-12-30 2012-08-08 上海华为技术有限公司 网络发现方法、装置和接入点
DE102010021256A1 (de) 2010-05-21 2011-11-24 Siemens Aktiengesellschaft Verfahren zur dynamischen Autorisierung eines mobilen Kommunikationsgerätes
US8516556B2 (en) * 2010-05-28 2013-08-20 Bridgewater Systems Corp. Methods for server-driven packet congestion control
US8613052B2 (en) 2010-09-17 2013-12-17 Universal Secure Registry, Llc Apparatus, system and method employing a wireless user-device
CN102685742B (zh) * 2011-03-15 2016-01-27 ***通信集团公司 一种wlan接入认证方法和装置
EP2562704A1 (fr) * 2011-08-25 2013-02-27 TeliaSonera AB Procédé de paiement en ligne et élément de réseau, système et produit de programme informatique correspondant
US8949959B2 (en) 2012-02-21 2015-02-03 Cisco Technology, Inc. Reduced authentication times for shared-media network migration
TWI538538B (zh) * 2014-08-27 2016-06-11 普易科技股份有限公司 居家控制閘道器及其閘道連線方法
US9565185B2 (en) 2014-11-24 2017-02-07 At&T Intellectual Property I, L.P. Facilitation of seamless security data transfer for wireless network devices
TWI622278B (zh) * 2016-04-13 2018-04-21 國立清華大學 使用模仿近場通訊之無線通訊系統及其認證方法
CN108924832B (zh) * 2017-04-14 2023-02-21 瑞典爱立信有限公司 用于安全Wi-Fi通话的方法、设备和***
CN108040044B (zh) * 2017-12-07 2019-06-07 恒宝股份有限公司 一种实现eSIM卡安全认证的管理方法及***
US10764266B2 (en) 2018-06-19 2020-09-01 Cisco Technology, Inc. Distributed authentication and authorization for rapid scaling of containerized services
US11792288B2 (en) * 2019-09-09 2023-10-17 Extreme Networks, Inc. Wireless network device with directional communication functionality
US11805112B2 (en) * 2021-02-08 2023-10-31 Cisco Technology, Inc. Enhanced multi-factor authentication based on physical and logical proximity to trusted devices and users
CN117425891A (zh) * 2021-06-07 2024-01-19 华为技术有限公司 用于支持基于网络的计算服务的***和方法

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050273513A1 (en) * 2001-06-13 2005-12-08 Citrix Systems, Inc. Systems and methods for continuing an operation interrupted from a reconnection between a client and server

Family Cites Families (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2307409A (en) 1995-11-22 1997-05-28 Spectron Laser Systems Ltd Therapeutic lamp apparatus
US5862481A (en) 1996-04-08 1999-01-19 Northern Telecom Limited Inter-technology roaming proxy
US6332077B1 (en) 1999-07-29 2001-12-18 National Datacom Corporation Intelligent roaming in AGV application
US7237261B1 (en) * 1999-09-07 2007-06-26 Swisscom Ag Method, system and gateway allowing secured end-to-end access to WAP services
US6587680B1 (en) 1999-11-23 2003-07-01 Nokia Corporation Transfer of security association during a mobile terminal handover
FI20000760A0 (fi) * 2000-03-31 2000-03-31 Nokia Corp Autentikointi pakettidataverkossa
AU2001244362A1 (en) 2000-04-10 2001-10-23 British Telecommunications Public Limited Company Provision of secure access for telecommunications system
FI20001837A (fi) * 2000-08-18 2002-02-19 Nokia Corp Autentikointi
US6691227B1 (en) 2000-09-08 2004-02-10 Reefedge, Inc. Location-independent packet routing and secure access in a short-range wireless networking environment
JP3628250B2 (ja) 2000-11-17 2005-03-09 株式会社東芝 無線通信システムで用いられる登録・認証方法
US7383329B2 (en) * 2001-02-13 2008-06-03 Aventail, Llc Distributed cache for state transfer operations
US20030061503A1 (en) * 2001-09-27 2003-03-27 Eyal Katz Authentication for remote connections
WO2003010946A1 (fr) * 2001-07-23 2003-02-06 Securelogix Corporation Encapsulation, compression et cryptage de donnees pcm
CN1177445C (zh) * 2001-09-29 2004-11-24 华为技术有限公司 一种pc客户端的安全认证方法
US7206826B1 (en) * 2001-10-25 2007-04-17 Sprint Communications Company L.P. Configuration recovery after gateway failure
US7249379B2 (en) * 2002-02-01 2007-07-24 Systems Advisory Group Enterprises, Inc. Method and apparatus for implementing process-based security in a computer system
AU2003212638A1 (en) * 2002-03-13 2003-09-22 Adjungo Networks Ltd. Accessing cellular networks from non-native local networks
US7418596B1 (en) * 2002-03-26 2008-08-26 Cellco Partnership Secure, efficient, and mutually authenticated cryptographic key distribution
US7503065B1 (en) * 2002-04-24 2009-03-10 Sprint Spectrum L.P. Method and system for gateway-based authentication
US7930753B2 (en) * 2002-07-01 2011-04-19 First Data Corporation Methods and systems for performing security risk assessments of internet merchant entities
US7426195B2 (en) * 2002-10-24 2008-09-16 Lucent Technologies Inc. Method and apparatus for providing user identity based routing in a wireless communications environment
US7346772B2 (en) 2002-11-15 2008-03-18 Cisco Technology, Inc. Method for fast, secure 802.11 re-association without additional authentication, accounting and authorization infrastructure
AU2003276588A1 (en) * 2002-11-18 2004-06-15 Nokia Corporation Faster authentication with parallel message processing
US7249177B1 (en) * 2002-11-27 2007-07-24 Sprint Communications Company L.P. Biometric authentication of a client network connection
US7434044B2 (en) 2003-02-26 2008-10-07 Cisco Technology, Inc. Fast re-authentication with dynamic credentials
US7506370B2 (en) * 2003-05-02 2009-03-17 Alcatel-Lucent Usa Inc. Mobile security architecture
US20060185013A1 (en) * 2003-06-18 2006-08-17 Telefonaktiebolaget Lm Ericsson (Publ) Method, system and apparatus to support hierarchical mobile ip services
US7305705B2 (en) * 2003-06-30 2007-12-04 Microsoft Corporation Reducing network configuration complexity with transparent virtual private networks
CN1529258A (zh) * 2003-09-29 2004-09-15 上海格尔软件股份有限公司 实现web应用安全加固的快速部署方法
US7272397B2 (en) * 2003-10-17 2007-09-18 Kineto Wireless, Inc. Service access control interface for an unlicensed wireless communication system
CN100459563C (zh) * 2003-11-21 2009-02-04 维豪信息技术有限公司 认证网关及其数据处理方法
US7046647B2 (en) * 2004-01-22 2006-05-16 Toshiba America Research, Inc. Mobility architecture using pre-authentication, pre-configuration and/or virtual soft-handoff
TWI249316B (en) * 2004-02-10 2006-02-11 Ind Tech Res Inst SIM-based authentication method for supporting inter-AP fast handover
US7280826B2 (en) * 2005-02-01 2007-10-09 Telefonaktiebolaget Lm Ericsson (Publ) Method, system and apparatus for providing security in an unlicensed mobile access network or a generic access network
US8356171B2 (en) 2006-04-26 2013-01-15 Cisco Technology, Inc. System and method for implementing fast reauthentication
US20080229416A1 (en) * 2007-01-09 2008-09-18 G. K. Webb Services Llc Computer Network Virus Protection System and Method

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050273513A1 (en) * 2001-06-13 2005-12-08 Citrix Systems, Inc. Systems and methods for continuing an operation interrupted from a reconnection between a client and server

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2011270A4 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109413646A (zh) * 2017-08-16 2019-03-01 华为技术有限公司 安全接入方法、设备及***

Also Published As

Publication number Publication date
WO2007127035A2 (fr) 2007-11-08
EP2011270A4 (fr) 2010-06-30
CN101432717B (zh) 2011-07-27
US20070256120A1 (en) 2007-11-01
EP2011270A2 (fr) 2009-01-07
CN101432717A (zh) 2009-05-13
US8356171B2 (en) 2013-01-15
EP2011270B1 (fr) 2020-10-07

Similar Documents

Publication Publication Date Title
WO2007127035A3 (fr) Systeme et procede de mise en œuvre de re-authentification rapide
WO2006099540A3 (fr) Systeme et procede pour distribuer les cles dans un reseau sans fil
WO2011123671A3 (fr) Authentification mobile mutuelle à l'aide d'un centre de gestion de clés
WO2010077910A3 (fr) Sécurité améliorée pour des communications en liaison directe
EP1758417A4 (fr) Procede d'authentification
WO2006091396A3 (fr) Securite de la couche de charge utile destinee au transfert de fichiers
CN108259407B (zh) 一种基于时间戳的对称加密方法及***
WO2009148261A3 (fr) Procédé de déduction et de mise à jour de clé de cryptage de trafic
WO2008039582A3 (fr) Système et procédé pour sécuriser les applications logicielles
NZ728318A (en) Networked access control system
WO2012068078A3 (fr) Système et procédé d'authentification de transaction à l'aide d'un dispositif de communication mobile
WO2005065132A3 (fr) Systeme, procede, et dispositifs pour l'authentification dans un reseau local sans fil
WO2004051964A3 (fr) Protocole d'authentification tunnellise empechant les attaques de l'intermediaire cache
WO2007050227A3 (fr) Infrastructure de communication de machine a affranchir, accessible via un fournisseur de services
WO2009048574A3 (fr) Communication sans fil sécurisée
WO2009026049A3 (fr) Appareil et procédé pour authentifier un dispositif réseau
CN103685282A (zh) 一种基于单点登录的身份认证方法
WO2008054407A3 (fr) Cryptage asynchrone pour des communications électroniques sécurisées
WO2006027650A3 (fr) Authentification de service
WO2012088408A3 (fr) Réseau de jonction de dispositif sans fil sécurisé de système cellulaire
WO2009031112A3 (fr) NœUD POUR RÉSEAU ET PROCÉDÉ D'ÉTABLISSEMENT D'UNE ARCHITECTURE DE SÉCURITÉ DISTRIBUÉE POUR RÉSEAU
WO2007081588A3 (fr) Generation repartie de donnees de cles de securite, basee sur des jetons
WO2009105525A3 (fr) Procédé et appareil de communication sécurisée sous un protocole de radio bidirectionnelle numérique
MX2010003377A (es) Metodo para autenticar unidades moviles unidas a una femtocelula en comunicacion con una red central segura como un subsistema multimedia de protocolo de internet.
CN101917270A (zh) 一种基于对称密码的弱认证和密钥协商方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 07755042

Country of ref document: EP

Kind code of ref document: A2

WWE Wipo information: entry into national phase

Ref document number: 2007755042

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 200780015228.6

Country of ref document: CN

NENP Non-entry into the national phase

Ref country code: DE